Sign inSign up
Cosign

dhi.io/cosign

Cosign 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.6-debian-dev, 2.6-debian13-dev, 2.6-dev, 2.6.5-debian-dev, 2.6.5-debian13-dev, 2.6.5-dev

Index digest:

sha256:a3b1981eba75ad56c6a197ecde8fe6d55071c4f74987eacf9e5c5cd4ddea3ebd

Manifest digest:

sha256:7748cb2fa1847f1b5cefa45e9d09a44b36a2eff8e27b6351b65f8c0df008c45a

Size

71.61 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cosign:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cosign:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cosign@sha256:cb6e374ad72e61b6777b4a038ccb8255636cb41bb747c70b07084538d659e9a7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cosign@sha256:0cda74ab18e1141812bc5a0768f2f94845ae8d19f8206932855fad8f5a0d378a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cosign@sha256:b02e6578d3bc05bb5d25c940839d7ec3cca06fead4464b28bf2b39d51330f660
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cosign@sha256:d0ebd7d0d92274fc63418929aec435cbb28d96602e8bf3f9214de974f9b2bc91
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cosign@sha256:1b3bd0fc710371bc52f5d9a1b323f873b34105f204eb928098d2a95db717006c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cosign@sha256:457401b6c8f0bf4c4b87e0cb875ad234220b33f65963a9beac0a8f164163f2b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cosign@sha256:76715a029944a476ea89b483fa0498e8d0686b9058ba568e5abec2a4da65ec3c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cosign@sha256:50acd8a916af45739635c7cacb8c5cbb7b26a6aa3ca9d0bf56c9bf2e15af01fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cosign@sha256:51c844fe2ee2dc037fc05a53b669fbe67a7732ba01cb897ec5fffbfa6b2ddf0c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cosign@sha256:c1e9e58eb1c9b4ec05de940aa79eb3e8644a6adec665dff167efbdabe002095c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cosign@sha256:9b541593148786e7b2a2d902fb4d0732692ad906deb5c50d3ff57c11bc15757d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cosign@sha256:7b0e8ffc1e0b550d478a03f84d3ccb804711184d7f5d538d6eb5f3c834bd3c11
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cosign@sha256:9d4768acc62d92100291e029d3443141113e9a8e18fd9724b44edf68c0a00436
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cosign@sha256:740349f24bc590ea6c3822b620901c7124167a32e37ba2aa7df7f5f851137d72
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cosign@sha256:149a939f908d00c227a0899e3031424e2162dc92c73fd86e3207d458d405c0c5